18-10
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter18 Configuring the ASA 5500-X IPS SSP
The ASA5500-X I PSSS P and the Normalizer Engine
The SensorApp is Reconfigured
The following occurs when the SensorApp is reconfigured:
If set to fail-open, the adaptive security appliance passes traffic without sending it to the ASA IPS
module.
If set to fail-close, the adaptive security appliance stops passing traffic until the ASAIPS module is
restarted.
Note
The adaptive security appliance does not fail over unless the reconfiguration is not completed.
The ASA 5500-X IPS SSP and the Normalizer Engine
The majority of the features in the Normalizer engine are not used on the ASA5500-X IPS SSP, because
the ASA itself handles the normalization. Packets on the ASA IPS modules go through a special path in
the Normalizer that only reassembles fragments and puts packets in the right order for the TCP stream.
The Normalizer does not do any of the normalization that is d one on an inline IPS appliance, because
that causes problems in the way the ASA handles the packets.
The following Normalizer engine signatures are not supported :
1300.0
1304.0
1305.0
1307.0
1308.0
1309.0
1311.0
1315.0
1316.0
1317.0
1330.0
1330.1
1330.2
1330.9
1330.10
1330.12
1330.14
1330.15
1330.16
1330.17
1330.18